1

Governance Risk And Compliance Jobs in Silver Spring, MD

Procurement Risk & Compliance Lead

Centreville, VA · On-site

$155K/yr

Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head of ...

Procurement Risk & Compliance Lead

Centreville, VA · On-site

$155K/yr

Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head of ...

next page

Showing results 1-20

Governance Risk And Compliance information

See Silver Spring, MD salary details

$102.3K

$198.2K

$397K

How much do governance risk and compliance jobs pay per year?

As of Jul 26, 2026, the average yearly pay for governance risk and compliance in Silver Spring, MD is $198,240.00, according to ZipRecruiter salary data. Most workers in this role earn between $174,200.00 and $196,900.00 per year, depending on experience, location, and employer.

What are Governance, Risk, and Compliance (GRC) roles?

Governance, Risk, and Compliance (GRC) roles are positions within organizations focused on ensuring that business operations align with legal standards, manage risk effectively, and follow internal policies. Professionals in GRC help organizations set up frameworks to oversee compliance with laws and regulations, identify and mitigate potential risks, and establish governance structures to guide decision-making. These roles are essential for protecting organizations from financial, legal, and reputational harm while promoting ethical practices and efficient processes.

What are the key skills and qualifications needed to thrive as a Governance, Risk, and Compliance (GRC) professional, and why are they important?

To thrive as a Governance, Risk, and Compliance (GRC) professional, you need a solid understanding of regulatory frameworks, risk assessment methodologies, and compliance requirements, often supported by a degree in business, finance, or a related field. Familiarity with GRC platforms (like RSA Archer or MetricStream), audit management tools, and relevant certifications such as CISA, CRISC, or CISSP is highly beneficial. Strong analytical thinking, attention to detail, and effective communication skills set top performers apart in this field. These skills are crucial for identifying risks, ensuring organizational compliance, and supporting informed decision-making to protect the business.

What are some common challenges faced by professionals in Governance, Risk, and Compliance (GRC) roles, and how can they be addressed?

Professionals in Governance, Risk, and Compliance (GRC) roles often face challenges such as staying updated with changing regulations, ensuring company-wide adherence to policies, and managing cross-functional collaboration. To address these, GRC specialists must develop strong communication skills to educate and train staff, leverage technology to automate compliance tracking, and build effective relationships with departments such as IT, legal, and operations. Regular professional development and proactive engagement with regulatory updates are also key to overcoming these challenges and maintaining effective governance.

What is the difference between Governance Risk And Compliance vs Compliance Analyst?

AspectGovernance Risk And ComplianceCompliance Analyst
CertificationsISO 31000, ISO 27001, Certified Risk Management ProfessionalCertified Compliance & Ethics Professional (CCEP), ISO 19600
Work EnvironmentCorporate, regulated industries, risk management departmentsLegal, audit, compliance departments within organizations
Employer & Industry UsageFinancial services, healthcare, energy, governmentFinancial institutions, healthcare, manufacturing, retail

Governance Risk And Compliance professionals focus on establishing frameworks, managing risks, and ensuring overall compliance strategies across organizations. Compliance Analysts primarily focus on implementing and monitoring specific compliance policies, often within legal or audit teams. While both roles require understanding regulations and certifications, Governance Risk And Compliance roles have a broader scope involving risk management and governance structures.

What are popular job titles related to Governance Risk And Compliance jobs in Silver Spring, MD? For Governance Risk And Compliance jobs in Silver Spring, MD, the most frequently searched job titles are:
What job categories do people searching Governance Risk And Compliance jobs in Silver Spring, MD look for? The top searched job categories for Governance Risk And Compliance jobs in Silver Spring, MD are:
What cities near Silver Spring, MD are hiring for Governance Risk And Compliance jobs? Cities near Silver Spring, MD with the most Governance Risk And Compliance job openings:
Infographic showing various Governance Risk And Compliance job openings in Silver Spring, MD as of July 2026, with employment types broken down into 100% Full Time. Highlights an 87% In-person, and 13% Remote job distribution, with an average salary of $198,240 per year, or $95.3 per hour.
Information Security Governance, Risk & Compliance (GRC) Analyst

Information Security Governance, Risk & Compliance (GRC) Analyst

ASSYST, Inc.

Rockville, MD

Full-time

Posted 19 hours ago


Job description

ASSYST is seeking an Information Security Governance, Risk & Compliance (GRC) Analyst to support our client in administering and maintaining an established enterprise Information Security Governance, Risk, and Compliance (GRC) program. This role will focus on managing Information Security Policy Exceptions and maintaining the Enterprise Information Security Risk Register using the ServiceNow Integrated Risk Management (IRM) platform.

The ideal candidate will work under the guidance of Information Security leadership to execute established governance processes, document and track information security risks, and support enterprise risk management activities. This position provides an excellent opportunity to gain hands-on experience with enterprise cybersecurity governance, information security risk management, ServiceNow IRM, and policy exception management while collaborating with experienced information security professionals.

Note: This position focuses on governance, documentation, and risk management activities. It does not involve performing security assessments, penetration testing, vulnerability assessments, audits, or compliance reviews.

Roles & Responsibilities:

  • Administer and support the Information Security Policy Exception Program.
  • Maintain and update the Enterprise Information Security Risk Register using the ServiceNow Integrated Risk Management (IRM) platform.
  • Execute established governance processes, standardized risk assessment methodologies, workflows, templates, and reporting procedures.
  • Review policy exception requests and document findings.
  • Perform information security risk analyses and provide approval or denial recommendations.
  • Document, track, and maintain identified information security risks within the enterprise Risk Register.
  • Prepare and maintain accurate policy exception tracking records.
  • Produce monthly metrics, quarterly reports, executive dashboards, and ServiceNow documentation.
  • Coordinate assigned tasks, workflows, and activities while ensuring timely completion.
  • Prepare clear and accurate technical documentation related to governance and risk management processes.
  • Collaborate with internal stakeholders to support enterprise information security governance initiatives.
  • Maintain high standards of documentation accuracy, consistency, and data integrity.
  • Provide excellent customer service while supporting governance and risk management activities.
  • Work independently while effectively managing multiple priorities and deadlines.

Required Skills & Qualifications:
Minimum Qualifications:

  • Professional experience in Information Security, IT Governance, Compliance, Risk Management, Information Technology, Audit, or a related field.
  • Basic understanding of Information Security Governance, Risk Management, and Cybersecurity principles.
  • Strong analytical and critical thinking skills.
  • Excellent written and verbal communication skills.
  • Strong organizational skills with exceptional attention to detail.
  • Ability to manage multiple priorities in a fast-paced environment.
  • Ability to quickly learn new technologies and business processes.
  • Demonstrated professionalism and ability to work independently.

Preferred Qualifications:

  • Experience using ServiceNow, preferably Integrated Risk Management (IRM).
  • Experience with Governance, Risk, and Compliance (GRC) programs or platforms.
  • Experience using Microsoft Office 365 applications.
  • Experience preparing technical documentation and reports.
  • Experience coordinating projects, tasks, or workflow activities.
  • Experience working in customer service or stakeholder-facing environments.

Knowledge & Technical Skills:

  • Cybersecurity Principles
  • Information Security Governance
  • Governance, Risk & Compliance (GRC)
  • Enterprise Risk Management
  • Risk Assessment Methodologies
  • Risk Register Management
  • ServiceNow Integrated Risk Management (IRM)
  • NIST Cybersecurity Framework (NIST CSF)
  • Risk Scoring Systems and Quantitative Risk Frameworks
  • HIPAA
  • Technical Documentation
  • Workflow Coordination
  • Microsoft Office 365

ASSYST is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, disability, military status, national origin or any other characteristic protected under federal, state, or applicable local law.